Back Home

Open Designs

Community. Driven.

    • CommentAuthorrefueled
    • CommentTimeJan 5th 2007
     
    What's new with Wordpress 2.0.6?

    * The aforementioned security fixes.
    * HTML quicktags now work in Safari browsers.
    * Comments are filtered to prevent them from messing up your blog layout.
    * Compatibility with PHP/FastCGI setups.

    Click here to download from Wordpress.org.
    •  
      CommentAuthorSean
    • CommentTimeJan 5th 2007 edited by Sean on the 05th January 2007 at 16:51:05 EST
     
    I upgraded my site yesterday. It's one more step closer to WordPress 2.1.

    It's highly recommended to upgrade if you're running an older 2.0.x version of WordPress because of the security fixes and patches made with the new release.

    If anyone needs some help doing an upgrade, let me know and I'll help you out no problem.
    • CommentAuthorrefueled
    • CommentTimeJan 5th 2007
     
    I am hearing that this will probably be the last update before 2.1 comes out. Lets hope so.
    •  
      CommentAuthorSean
    • CommentTimeJan 5th 2007
     
    Yep, that's the official word on the WordPress Blog.
    •  
      CommentAuthorgnome
    • CommentTimeJan 5th 2007
     
    Has opendesigns moved to 2.0.6, or is the code too modded to patch?
    •  
      CommentAuthordarkfate
    • CommentTimeJan 5th 2007
     
    • CommentAuthorainslie
    • CommentTimeJan 5th 2007
     
    As always make backups before upgrading. Database and files.

    bigsmile
    •  
      CommentAuthorSean
    • CommentTimeJan 5th 2007
     
    @Gnome: What we've done with OpenDesigns.org and WordPress doesn't touch any core files, however with the forum integration, we have one area, the user base, that is shared, so we are doing off site testing with the new WP upgrade to make sure everything works and nothing is changed in the user table in WordPress.

    @Ainslie: We have plenty of backups going on for the site, so we can recover if we have any sort of issue but as I said above, we're doing off site testing of the new version before we move it here live.
    • CommentAuthorainslie
    • CommentTimeJan 6th 2007
     
    Excellent smile

    Usually there isn't a problem but sometimes plugins cause a few issues and I am always over cautious.
    • CommentAuthor4evrblu
    • CommentTimeJan 6th 2007 edited by 4evrblu on the 06th January 2007 at 06:33:59 EST
     
    I have 2.05 and was wondering if I can get by without an upgrade or is it necessary to bump it from 2.05 to 2.06.

    What do you think?

    In any case, 2.06 has only been out a few hours. Wouldn't be wise to wait a couple days and see if they have identified any issues? Plus, many of our plugin authors will need time to update their plugins won't they?
    •  
      CommentAuthorChristopher
    • CommentTimeJan 6th 2007 edited by Christopher on the 06th January 2007 at 06:32:58 EST
     
    Upgrade, Upgrade, Upgrade.

    WordPress is vulnerable to cross-site scripting, caused by improper validation of user-supplied input by the get_file_description() function. A remote attacker could exploit this vulnerability using unspecifed parameters in a specially-crafted URL request to the templates.php script to execute script in a victim's Web browser within the security context of the hosting Web site, once the URL is clicked. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

    The above was a major security flaw in 2.0.5 and has been fixed in the 2.0.6 release :)
    • CommentAuthor4evrblu
    • CommentTimeJan 6th 2007
     
    OK ia guess that answers part of my question. I suppose the other part is why not wait a day or so :P This version might have buggies of its own :D
    • CommentAuthorainslie
    • CommentTimeJan 6th 2007
     
    I've tested quite a bit now and all seems well. Just spent quite a while upgrading several sites and nothing broke yet but it is a right pain when there are a few sites to do.

    If you do a database backup and then download all your current files with ftp then you can always roll it back if you do have problems.

    If you want to wait, at least upload and overwrite the templates.php file in wp-admin as this is where the security problem was.
    •  
      CommentAuthorChristopher
    • CommentTimeJan 6th 2007 edited by Christopher on the 06th January 2007 at 06:57:08 EST
     
    At least update the templates.php file as thats where the major flaw is.

    EDIT: Ainslie beat me to it!!
    •  
      CommentAuthorJeremyD
    • CommentTimeJan 6th 2007
     
    I upgraded last night...without backing my stuff up. I'm a web design dare devil :P
    • CommentAuthorainslie
    • CommentTimeJan 6th 2007
     
    Sorry Christopher shamed

    ...and speaking of bugs here's the first and the fix: Here
    • CommentAuthor4evrblu
    • CommentTimeJan 6th 2007
     
    Posted By: JeremyDI upgraded last night...without backing my stuff up. I'm a web design dare devil :P



    LOOLOLOL ROFLrolling
    • CommentAuthor4evrblu
    • CommentTimeJan 6th 2007
     
    About the wp-include directory-

    I am confused by this statement that says delete everything except for, among other things, the:

    "wp-includes/languages/ folder--if you are using a language file do not delete that folder;"

    Does that mean that if there is NOT a subfolder within wp-includes called "languages", then we should delete the entire wp-includes folder/directory?
    • CommentAuthor4evrblu
    • CommentTimeJan 6th 2007 edited by 4evrblu on the 06th January 2007 at 09:27:50 EST
     
    my FTP keeps timing out when I try to upload 2.06. Never happened before. What the F!

    I will try uploaded in Passive Transfer Mode. See if that helps
    • CommentAuthorrefueled
    • CommentTimeJan 6th 2007
     
    @4evrblu:

    restart you machine, spin around 13 times, and say sit while holding your tongue. That should solve your issue. bigsmile
    • CommentAuthor4evrblu
    • CommentTimeJan 6th 2007
     
    HAHAHAH
    • CommentAuthor4evrblu
    • CommentTimeJan 6th 2007
     
    OK now were cooking on all four burners baby!!! No wonder my a$$ is on fire! Oh wait.... that must have been them Jalapenos I ate last night shocked
    • CommentAuthor4evrblu
    • CommentTimeJan 6th 2007
     
    OOPS!

    http://cfcure.com/wordpresss/wp-admin/upgrade.php gave me

    Internal Server Error

    The server encountered an internal error or misconfiguration and was unable to complete your request.
    Please contact the server administrator, support@supportwebsite.com and inform them of the time the error occurred, and anything you might have done that may have caused the error.

    More information about this error may be available in the server error log.
    • CommentAuthor4evrblu
    • CommentTimeJan 6th 2007
     
    ~thinks to himself~

    "That's because wordpress is spelled with two S's you moron, not 3 S's! Sheesh...."
    •  
      CommentAuthorSean
    • CommentTimeJan 6th 2007
     
    WordPress 2.0.6 was in two different beta testing phases which I took part in. There were two Release Candidates with a ton of testing, so it's good to go.

    I have also done testing for the upgrade on a local server with an exact mirror of the OpenDesigns.org site and it went fine, so once the site had only a few people on it, I'll be doing the upgrade.

    If I did it now, things would stop working for a few minutes while files updated.
    •  
      CommentAuthordarkfate
    • CommentTimeJan 6th 2007
     
    Apparently there is some weird errors with people getting 500 errors. I'm not sure what's causing it. There was also a feed problem that was fixed. Looks like 2.0.7 is coming soon.
    •  
      CommentAuthorSean
    • CommentTimeJan 6th 2007 edited by Sean on the 06th January 2007 at 12:42:28 EST
     
    Version 2.0.6 was just released after a ton of beta and bug testing.

    The 500 errors were corrected in a WordPress 2.0.5 tune up file and have also now been fixed in 2.0.6.

    I read on the WordPress blog that 2.0.6 is the last update before 2.1 comes out but they will continue to make updates and fixes for the 2.0.x branch for a couple years which is nice.

    Also, we are now running WordPress 2.0.6 bigsmile
    •  
      CommentAuthorSean
    • CommentTimeJan 6th 2007
     
    Apparently there was one small bug with RSS feeds and FeedBurner that slipped into version 2.0.6 and there is a fix from Mark Jaquith one of the lead WordPress developers.

    I've already made the fix on OpenDesigns.org and my personal site as well.
    • CommentAuthorrefueled
    • CommentTimeJan 6th 2007 edited by Sean on the 27th June 2008 at 01:40:50 EDT
     
    Posted By: sean
    Also, we are now running WordPress 2.0.6

    nice. I have yet to upgrade my site.
    •  
      CommentAuthorJosh
    • CommentTimeJan 6th 2007
     
    Well, it was about time for me to upgrade from 2.0.3 ;)

    Upgrade went flawless. :)
    • CommentAuthorainslie
    • CommentTimeJan 6th 2007
     
    Open source, don't you just love it rainbow
    • CommentAuthorrefueled
    • CommentTimeJan 6th 2007 edited by Sean on the 06th January 2007 at 14:29:00 EST
     
    Posted By: ainslieOpen source, don't you just love it rainbow


    I praise anything Open Source. whorship
  1.  
    The only downside to Open Source is that the source code is available free of charge to anyone who wants, which is the main reason to upgrade whenever possible. As anyone can get their hands on the base that your site is running off, which means they can search for exploits. One of the major downsides to Open Source is also the main advantage to it, oh how fun isn't it haha.
    •  
      CommentAuthorJosh
    • CommentTimeJan 6th 2007
     
    Posted By: christopherThe only downside to Open Source is that the source code is available free of charge to anyone who wants, which is the main reason to upgrade whenever possible. As anyone can get their hands on the base that your site is running off, which means they can search for exploits. One of the major downsides to Open Source is also the main advantage to it, oh how fun isn't it haha.


    Exactly. I remember one phpbb exploit that let you pretty much run any shell command you wanted on unpatched phpbb installs. It was crazy simple. I "hacked" a friend of mine and completely freaked him out. (didn't do anything malicious, just made an index.html file suggesting an ugprade)
    •  
      CommentAuthorSean
    • CommentTimeJan 6th 2007 edited by Sean on the 06th January 2007 at 14:47:23 EST
     
    With exploits and Open Source, good developers and people who find problems in code should always let the original developer or company know about the issue so it can be fixed, in private.

    This is reason why it's always good to keep up to date on programs and code, especially Open Source stuff.

    Once a bug or security issue is properly fixed, then it should be made public what the issue was and of course, people should listen and upgrade properly to have a safer and more secure internet experience bigsmile